ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1036.005×

63 examples

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
GroupINC Ransom

INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file.

T1036.005
Match Legitimate Resource Name or Location
GroupEarth Lusca

Earth Lusca used the command `move [file path] c:\windows\system32\spool\prtprocs\x64\spool.dll` to move and register a malicious DLL name as a Windows print processor, which eventually was loaded by the Print Spooler service.

T1036.005
Match Legitimate Resource Name or Location
GroupSilence

Silence has named its backdoor "WINWORD.exe".

T1036.005
Match Legitimate Resource Name or Location
GroupSowbug

Sowbug named its tools to masquerade as Windows or Adobe Reader software, such as by using the file name adobecms.exe and the directory CSIDL_APPDATA\microsoft\security.

T1036.005
Match Legitimate Resource Name or Location
GroupVelvet Ant

Velvet Ant used a malicious DLL, `iviewers.dll`, that mimics the legitimate "OLE/COM Object Viewer" within Windows.

T1036.005
Match Legitimate Resource Name or Location
GroupTransparent Tribe

Transparent Tribe can mimic legitimate Windows directories by using the same icons and names.

T1036.005
Match Legitimate Resource Name or Location
GroupVOID MANTICORE

VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications. VOID MANTICORE has leveraged malicious payloads that use nomenclature associated with common applications that include Pictory, KeePass, WhatsApp, and Telegram.

T1036.005
Match Legitimate Resource Name or Location
GroupPROMETHIUM

PROMETHIUM has disguised malicious installer files by bundling them with legitimate software installers.

T1036.005
Match Legitimate Resource Name or Location
GroupWIRTE

WIRTE has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
GroupMagic Hound

Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink.

T1036.005
Match Legitimate Resource Name or Location
GroupFIN13

FIN13 has masqueraded WAR files to look like legitimate packages such as, wsexample.war, wsexamples.com, examples.war, and exampl3s.war.

T1036.005
Match Legitimate Resource Name or Location
GroupTeamPCP

TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits. TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads.

T1036.005
Match Legitimate Resource Name or Location
GroupShinyHunters

ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.